Back to wire
Development·Article·Confirmed

CrowdSec confirms private source-code exposure from May

CrowdSec says private GitHub repositories containing code for its SaaS console, AWS cloud routines, connectors and automations were exposed in May 2026. The security company says it has found no customer data or usable credential exposure so far and considers a compromised TanStack component the likely route, while that cause and the full impact remain under investigation.

Published 17 Sept 2026, 12:27 · Updated 17 Sept 2026, 19:21

CrowdSec confirms private repositories were exposed

CrowdSec says it was informed on 16 September that private source code from its GitHub repositories had been exposed in May 2026, and that its team verified the report. The company says the affected private code covers its SaaS console, some AWS cloud routines, connectors and automations. CrowdSec's open-source Security Engine is public by design and is outside the private-code exposure.

The company also clarifies reports referring to roughly 300 repositories. It says that count is accurate only when more than 130 already-public repositories are included and largely reflects how its code is divided. CrowdSec says the private exposure itself did not include separate internal-development material beyond the repositories.

Customer impact is limited according to the company

CrowdSec says its investigation has so far found no leaked client data, login credentials, names, organisation details, client logs or other personally identifying customer information. It also says a search for exposed tokens, credentials or other secrets that could enable lateral movement has not found any so far, and that it rotated relevant tokens and credentials after learning of the incident.

Those statements describe CrowdSec's current investigation rather than an independent forensic audit. A source-code leak can still expose implementation details useful to an attacker even when customer records are absent, and CrowdSec says it will continue monitoring for abnormal activity. The public statement does not provide a complete inventory of every private repository or an external assessment of downstream risk.

CrowdSec points to a suspected supply-chain route

CrowdSec says a compromised TanStack component used inside the organisation in May is the very likely leak vector. According to the company, the component appears to have been backdoored to extract an API key with permission to read the private codebase, and the exposure window was short. That explanation is CrowdSec's attribution while the investigation continues.

The statement links the suspected route to a broader TanStack supply-chain compromise previously discussed in connection with Mistral AI. CrowdSec has not published a forensic timeline showing every step from the compromised dependency to repository access, so the existence of the code exposure is confirmed by the company while the precise intrusion chain remains less settled.

What remains unresolved

The incident became public roughly four months after the exposure occurred. CrowdSec says much of the code changed during that period and argues that its service depends heavily on data and network effects that cannot be reproduced from source code alone. Those factors may reduce some forms of reuse, but they do not establish that the exposed code has no security value.

The next material update should be a fuller incident report or independent corroboration covering the repositories accessed, the API key's effective permissions, whether any secrets were present at the time of access, and the evidence tying the event to the suspected TanStack compromise. Until then, customer-impact and root-cause claims should remain attributed to CrowdSec rather than presented as independently verified facts.

Source trail

2 sources · 1 primary · 1 community